Healthcare organizations already report breaches to two or three authorities on different clocks, and a pending CISA rule will add another.

 

What happened

Roughly 70% of federal cybersecurity regulations contain redundant reporting requirements, according to Cybersecurity Dive's coverage of a Government Accountability Office report published July 22, 2026. GAO counted 117 cybersecurity rules issued by 37 federal agencies across nine critical infrastructure sectors, and found that 80 of them cover the same ground. Those 80 rules carry at least 125 distinct reporting obligations between them. The study was requested by House Homeland Security Chairman Andrew Garbarino, a New York Republican, and Senator Gary Peters, a Michigan Democrat and ranking member of the Senate counterpart committee, as CyberScoop reported.

 

Going deeper

The 125 requirements break into three categories that ask organizations for different things at different times. Forty-eight regulations require reporting of cybersecurity incidents, 52 require cybersecurity plans or other technical information, and 25 require reviews, audits, or assessments, GAO found. Some regulations impose more than one type. A single organization can therefore owe an incident report to one agency, a security plan to a second, and audit results to a third, each with its own definition of what counts as reportable and its own deadline. Cross-sector rules compound the problem, since a publicly traded healthcare company falls under Securities and Exchange Commission disclosure requirements alongside whatever its sector regulator demands.

 

What was said

Organizations subject to overlapping audit provisions "may be required to provide duplicative compliance data or conduct multiple compliance audits," GAO wrote in the report, noting that those audits can differ in scope, depth, and methodology while examining the same systems. The agency was blunt about what happens next, warning that without harmonization the pending CISA rule under the Cyber Incident Reporting for Critical Infrastructure Act will make the redundancy worse, as Cybersecurity Dive reported on July 22, 2026.

 

In the know

GAO asked the regulated organizations themselves what the overlap costs them, convening industry panels in May and September 2025 and publishing the results in a separate report in March 2026. Participants pointed less at the number of rules than at the mismatches between them, describing frameworks with similar controls separated by small differences that create confusion rather than added security. On incident reporting specifically, they said agencies request different amounts of information within different windows and apply different standards for when an incident becomes reportable at all. One participant described the difficulty of assembling information for multiple recipients inside a short window, which is the practical problem a security team faces during the first days of an active incident. The panels included cybersecurity and IT directors, general counsels, and chief information officers.

 

The big picture

Healthcare and public health is one of the sixteen sectors CIRCIA will cover, and hospitals already carry a notification stack that runs on separate clocks. A HIPAA breach affecting 500 or more individuals goes to OCR within 60 days of discovery, state attorneys general operate on their own timelines, and CIRCIA would add a 72-hour report to CISA for substantial incidents plus a 24-hour report for ransomware payments. Those clocks run during the same days a team is trying to contain an intrusion and determine what was taken. Paubox's Hidden Cost of Inaction report found 73% of healthcare IT leaders expecting more email-related breaches ahead, which means more organizations having to deal with that reporting maze rather than fewer. Compliance teams would do well to map their reporting obligations now, including who files what and to whom, rather than assembling that map under pressure.

 

FAQs

What is CIRCIA and when does it take effect?

The Cyber Incident Reporting for Critical Infrastructure Act of 2022 directs CISA to require covered entities in the sixteen critical infrastructure sectors to report substantial cyber incidents within 72 hours and ransom payments within 24 hours. CISA is still finalizing the rule, and the compliance date follows publication of the final version rather than the statute's passage.

 

Does a CIRCIA report replace a HIPAA breach notification?

No. The obligations are separate, run to different agencies, and use different triggers. A CIRCIA report concerns a substantial cyber incident regardless of whether protected health information was involved, while HIPAA notification turns on unauthorized access to PHI.

 

Who is responsible for harmonizing these requirements?

The Office of the National Cyber Director holds the coordinating role under federal law and the April 2024 National Security Memorandum-22. GAO's finding is that those efforts have not yet reduced the overlap, which is why members of Congress from both chambers requested the review.

 

Would reciprocity between agencies solve the problem?

Partially. Industry participants have proposed that agencies accept one another's reports and audit results where the underlying requirement matches, along with converging on common definitions of terms such as "incident" and "substantial." Neither change removes the obligation, though both reduce the number of separate submissions.

 

Does the overlap affect small provider organizations?

Yes, disproportionately. A large health system can staff a compliance function that tracks multiple regimes, while a small practice or regional lab often has one person handling the same obligations alongside other duties. The administrative burden lands hardest where there is least capacity to absorb it.